Zoom patched several high-severity security vulnerabilities, including a critical zero-click flaw in its annotation feature. The primary vulnerability, CVE-2026-53413 or Zoomsday, allowed meeting participants to remotely control another attendee's computer. This exploit required no user interaction beyond attending a meeting where screen-sharing was active.
The memory-corruption vulnerability affected Zoom clients on Windows, macOS, Linux, iOS, and Android. Attackers could exploit the flaw to install malware or steal sensitive data. The vulnerability also granted unauthorized access to a user's microphone and camera.
Zoom released security updates to address these issues across all supported platforms. The company reports no evidence that attackers have exploited the Zoomsday vulnerability in the wild.